...ypes where field names to replace are far less predictable. Our search heads have over 1000 KOs which referencethe xmlWinEventLog sourcetype.
Has anyone made the transition to SplunkAdd-onforWindows...
...counter then calculate the avg and stdev. Here is the query I have so far, mostly based ontheSplunk Docs Outlier information
index=perfmon collection=HTTP counter=CurrentConnections host=S...
...vent data from theSplunkAdd-onfor Microsoft Windows. What's the best way to migrate my Windowsperformance monitoring from event-based to metrics-based data?
I always saw these "OS" and "Windows" tags onthe eventtypes.conf and tags.conf. It's onthe production environment and splunkbase applications even we're only using default Splunk CIM. OS- can b...
So I am very new to Splunk and I have just started using it. What I want to do is be able to view my own laptops operating system file logs and performance data. What I have been doing is logging on...
...Microsoft Windows and theSplunkAdd-on Unix and Linux but I find that enumerating each sourcetype and coalescing the common fields is feeling unnecessarily complicated.
Are there any basic s...
I'm a Splunk administrator, not a Windows administrator, so my Windows knowledge is limited. Nonetheless, many teams can benefit from having Windows Event Log data in Splunk. What are the best p...